CVE-2025-25724

CVSS 3.1 Score 4 of 10 (medium)

Details

Published Mar 2, 2025
CWE ID 252

Summary

CVE-2025-25724 is a vulnerability affecting the list_item_verbose function in tar/util.c of libarchive before version 3.7.8. This issue stems from a failure to verify the return value of the strftime function, which could result in a denial of service or unspecified other impacts. Maliciously crafted TAR archives with verbose value 2 can potentially cause this vulnerability to manifest, with a 100-byte buffer being insufficient for custom locales.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share